What information is most essential for the board/executives to decide whether to pay ransomware attackers (in cases where ransom payment is not banned)?

1.8k views5 Comments
Sort By:
Oldest
IT Manager in Constructiona month ago
I believe you can't add more, the opinion are pay or not pay with the second one highly suggested.
I believe the board can only count the votes.
Vice President, Infrastructure Architect in Finance (non-banking)a month ago
A *realistic* estimate of how long it will take to get back to full operations in either scenario.  Management needs to know what kind of costs/losses they incur in either case.  This is not the time to sugarcoat or attempt to be the hero/pull off a miracle.
Director of ITa month ago
It's a combination of the above.

There are several key inputs to the decision.  1.  Do you have a strong DR/ECP Plan and how long would it take for you to recover?  2. What is the loss of Revenue and Profit during this timeframe?  3. What Legal issues and costs  could also arise from being unable to provide services during this time? Are lives at risk?  4) What would it take to put safeguards in place to  prevent a repeat attack? 5) Lastly, what are the chances that payment of the ransom will truly prevent the attacker from coming after you again?  Overall, Paying a ramson should be a last resort and spending money up front to minimize the chances of a successful ransomware attack should  be strongly considered
1
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Director Of Information Technology in Manufacturinga month ago
A document recovery plan that has been documented, executed and proven. This provides insight for executives on what down time may be involved. 
Director of IT in Healthcare and Biotecha month ago
I agree with Evan Marks' comments.  The only thing I would add is making sure the board has been briefed by law enforcement as well.

Content you might like

CISO in Software21 days ago
It always starts with building a risk profile and D&R plan with cyber being a critical element of the D&R plan.
1
Read More Comments
425 views3 Comments

Human Factors (fears, mental health, physical spacing)85%

Technical / IT Factors (on-premise tools, pivoting back away from remote)14%

3.7k views3 Upvotes2 Comments

Implementation complete23%

Implementation in progress54%

Planned within the next 12 months12%

Not planned7%

Not enabling O365 on mobile2%

View Results
2.4k views2 Upvotes